5. ist leicht unvollständig, da mein Pc immer abstürzt, wenn ich ihn scannen lasse ;)
5. Code:
GMER 1.0.15.15281 - hxxp://www.gmer.net
Rootkit scan 2010-07-02 17:09:02
Windows 5.1.2600 Service Pack 3
Running: esqubuq8.exe; Driver: C:\DOKUME~1\Martin\LOKALE~1\Temp\uwloypog.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xA656678A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xA6566821]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xA6566738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xA656674C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xA6566835]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xA6566861]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xA65668CF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xA65668B9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xA65667CA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xA65668FB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xA656680D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xA6566710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xA6566724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xA656679E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xA6566937]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xA65668A3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xA656688D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xA656684B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xA6566923]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xA656690F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xA6566776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xA6566762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xA6566877]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xA65667F9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xA65668E5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xA65667E0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xA65667B4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwYieldExecution 804F0EB6 7 Bytes JMP A65667B8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwOpenKey 80568D48 5 Bytes JMP A6566811 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryValueKey 8056A1F9 7 Bytes JMP A6566891 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8056CF98 5 Bytes JMP A656678E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 8056DDD9 5 Bytes JMP A6566766 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateKey 80570833 5 Bytes JMP A6566825 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryKey 80570C4A 7 Bytes JMP A656693B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateKey 80570F41 7 Bytes JMP A65668D3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenProcess 805719AC 5 Bytes JMP A6566714 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80571E96 7 Bytes JMP A65667A2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetValueKey 80572A6E 7 Bytes JMP A656687B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 805738C6 5 Bytes JMP A65667E4 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 80573D41 7 Bytes JMP A65667CE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8057FE4C 2 Bytes JMP A6566750 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcessEx + 3 8057FE4F 4 Bytes [FE, 25, 90, 90]
PAGE ntoskrnl.exe!ZwTerminateProcess 805824CC 5 Bytes JMP A65667FD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateValueKey 80589A67 7 Bytes JMP A65668BD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 8058E5C4 5 Bytes JMP A6566728 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwNotifyChangeKey 8058EA94 5 Bytes JMP A65668FF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteValueKey 80592D64 7 Bytes JMP A6566865 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteKey 80595316 7 Bytes JMP A6566839 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805B14AC 5 Bytes JMP A656673C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 8062E057 5 Bytes JMP A656677A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnloadKey 8064DD32 7 Bytes JMP A65668E9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryMultipleValueKey 8064E66B 7 Bytes JMP A65668A7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRenameKey 8064EAEA 7 Bytes JMP A656684F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRestoreKey 8064EFDD 5 Bytes JMP A6566913 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwReplaceKey 8064F446 5 Bytes JMP A6566927 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
---- User code sections - GMER 1.0.15 ----
.text c:\PROGRA~1\GEMEIN~1\mcafee\mcproxy\mcproxy.exe[860] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C130 c:\PROGRA~1\GEMEIN~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\GEMEIN~1\mcafee\mcproxy\mcproxy.exe[860] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0041C1B0 c:\PROGRA~1\GEMEIN~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FB0FEF
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FB004A
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FB0F4B
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FB002F
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FB0F7C
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FB0F9E
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FB0071
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FB0F29
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FB0EE9
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FB0082
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FB0ED8
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FB0F8D
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FB0FD4
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FB0F3A
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FB0FC3
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FB000A
.text C:\WINDOWS\Explorer.EXE[896] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FB0F0E
.text C:\WINDOWS\Explorer.EXE[896] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00EC0FC3
.text C:\WINDOWS\Explorer.EXE[896] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00EC0F97
.text C:\WINDOWS\Explorer.EXE[896] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00EC0FD4
.text C:\WINDOWS\Explorer.EXE[896] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00EC0FEF
.text C:\WINDOWS\Explorer.EXE[896] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00EC0054
.text C:\WINDOWS\Explorer.EXE[896] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00EC0000
.text C:\WINDOWS\Explorer.EXE[896] ADVAPI32.dll!RegCreateKeyW 77DCBA55 2 Bytes JMP 00EC0FA8
.text C:\WINDOWS\Explorer.EXE[896] ADVAPI32.dll!RegCreateKeyW + 3 77DCBA58 2 Bytes [0F, 89]
.text C:\WINDOWS\Explorer.EXE[896] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00EC002F
.text C:\WINDOWS\Explorer.EXE[896] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00DF005A
.text C:\WINDOWS\Explorer.EXE[896] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00DF0049
.text C:\WINDOWS\Explorer.EXE[896] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00DF0FE3
.text C:\WINDOWS\Explorer.EXE[896] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00DF000C
.text C:\WINDOWS\Explorer.EXE[896] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00DF0038
.text C:\WINDOWS\Explorer.EXE[896] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00DF001D
.text C:\WINDOWS\Explorer.EXE[896] WININET.dll!InternetOpenA 408DD690 5 Bytes JMP 00D10000
.text C:\WINDOWS\Explorer.EXE[896] WININET.dll!InternetOpenW 408DDB09 5 Bytes JMP 00D10FDB
.text C:\WINDOWS\Explorer.EXE[896] WININET.dll!InternetOpenUrlA 408DF3A4 5 Bytes JMP 00D1001B
.text C:\WINDOWS\Explorer.EXE[896] WININET.dll!InternetOpenUrlW 40926DDF 5 Bytes JMP 00D1002C
.text C:\WINDOWS\Explorer.EXE[896] WS2_32.dll!socket 71A14211 5 Bytes JMP 00D20FEF
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00930FEF
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00930093
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00930082
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00930071
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0093004A
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00930FB9
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 009300BF
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 009300AE
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00930106
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009300EB
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00930121
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00930FA8
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0093000A
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00930F83
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00930025
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00930FD4
.text C:\WINDOWS\system32\services.exe[984] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 009300DA
.text C:\WINDOWS\system32\services.exe[984] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00920FB9
.text C:\WINDOWS\system32\services.exe[984] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00920039
.text C:\WINDOWS\system32\services.exe[984] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00920014
.text C:\WINDOWS\system32\services.exe[984] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00920FDE
.text C:\WINDOWS\system32\services.exe[984] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00920F72
.text C:\WINDOWS\system32\services.exe[984] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00920FEF
.text C:\WINDOWS\system32\services.exe[984] ADVAPI32.dll!RegCreateKeyW 77DCBA55 2 Bytes JMP 00920F8D
.text C:\WINDOWS\system32\services.exe[984] ADVAPI32.dll!RegCreateKeyW + 3 77DCBA58 2 Bytes [B5, 88] {MOV CH, 0x88}
.text C:\WINDOWS\system32\services.exe[984] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00920F9E
.text C:\WINDOWS\system32\services.exe[984] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00910FA3
.text C:\WINDOWS\system32\services.exe[984] msvcrt.dll!system 77BF93C7 5 Bytes JMP 0091002E
.text C:\WINDOWS\system32\services.exe[984] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00910FD2
.text C:\WINDOWS\system32\services.exe[984] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00910FEF
.text C:\WINDOWS\system32\services.exe[984] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 0091001D
.text C:\WINDOWS\system32\services.exe[984] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 0091000C
.text C:\WINDOWS\system32\services.exe[984] WS2_32.dll!socket 71A14211 5 Bytes JMP 00900000
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BA0000
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BA0F83
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BA0F94
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BA0062
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BA0FA5
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BA002C
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BA0F61
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BA0F72
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BA00DF
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BA00CE
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BA00F0
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BA0047
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BA0FE5
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BA009D
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BA0FCA
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BA001B
.text C:\WINDOWS\system32\lsass.exe[996] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BA0F46
.text C:\WINDOWS\system32\lsass.exe[996] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00B9002C
.text C:\WINDOWS\system32\lsass.exe[996] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00B90F94
.text C:\WINDOWS\system32\lsass.exe[996] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00B9001B
.text C:\WINDOWS\system32\lsass.exe[996] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00B90FEF
.text C:\WINDOWS\system32\lsass.exe[996] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00B90FA5
.text C:\WINDOWS\system32\lsass.exe[996] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00B9000A
.text C:\WINDOWS\system32\lsass.exe[996] ADVAPI32.dll!RegCreateKeyW 77DCBA55 2 Bytes JMP 00B90FB6
.text C:\WINDOWS\system32\lsass.exe[996] ADVAPI32.dll!RegCreateKeyW + 3 77DCBA58 2 Bytes [DC, 88]
.text C:\WINDOWS\system32\lsass.exe[996] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00B90047
.text C:\WINDOWS\system32\lsass.exe[996] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00B80053
.text C:\WINDOWS\system32\lsass.exe[996] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00B80FC8
.text C:\WINDOWS\system32\lsass.exe[996] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00B8002E
.text C:\WINDOWS\system32\lsass.exe[996] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00B80000
.text C:\WINDOWS\system32\lsass.exe[996] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00B80FD9
.text C:\WINDOWS\system32\lsass.exe[996] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00B80011
.text C:\WINDOWS\system32\lsass.exe[996] WS2_32.dll!socket 71A14211 5 Bytes JMP 00B70FEF
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B10FE5
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B10F52
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B10047
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B10F79
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B10F94
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B10036
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B10F21
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B10073
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B100B0
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B10095
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B10F06
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B10FAF
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B10FCA
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B10062
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B1001B
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B10000
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B10084
.text C:\WINDOWS\system32\svchost.exe[1184] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00B00FA8
.text C:\WINDOWS\system32\svchost.exe[1184] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00B00F86
.text C:\WINDOWS\system32\svchost.exe[1184] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00B00FB9
.text C:\WINDOWS\system32\svchost.exe[1184] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00B00FD4
.text C:\WINDOWS\system32\svchost.exe[1184] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00B00043
.text C:\WINDOWS\system32\svchost.exe[1184] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00B00FE5
.text C:\WINDOWS\system32\svchost.exe[1184] ADVAPI32.dll!RegCreateKeyW 77DCBA55 5 Bytes JMP 00B0001E
.text C:\WINDOWS\system32\svchost.exe[1184] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00B00F97
.text C:\WINDOWS\system32\svchost.exe[1184] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00AF0031
.text C:\WINDOWS\system32\svchost.exe[1184] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00AF0FA6
.text C:\WINDOWS\system32\svchost.exe[1184] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00AF0FC1
.text C:\WINDOWS\system32\svchost.exe[1184] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00AF0FEF
.text C:\WINDOWS\system32\svchost.exe[1184] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00AF0016
.text C:\WINDOWS\system32\svchost.exe[1184] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00AF0FD2
.text C:\WINDOWS\system32\svchost.exe[1184] WS2_32.dll!socket 71A14211 5 Bytes JMP 00A80000
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C00FEF
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C00F4B
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C00F5C
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C00036
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C00F79
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C00FA5
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C00F24
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C0006C
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C000A5
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C00F02
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C000B6
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C00F94
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C00000
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C0005B
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C00FC0
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C0001B
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C00F13
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00BF0FC3
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00BF0043
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00BF0014
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00BF0FD4
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00BF0F86
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyW 77DCBA55 2 Bytes JMP 00BF0F97
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyW + 3 77DCBA58 2 Bytes [E2, 88] {LOOP 0xffffffffffffff8a}
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00BF0FB2
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00BE0FA8
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00BE0FB9
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00BE0FDE
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00BE0FEF
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00BE0033
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00BE000C
.text C:\WINDOWS\system32\svchost.exe[1304] WS2_32.dll!socket 71A14211 5 Bytes JMP 00BD0000
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 029E0FEF
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 029E0075
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 029E0F80
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 029E005A
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 029E003D
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 029E0F9B
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 029E0F59
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 029E00AB
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 029E0F19
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 029E0F34
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 029E0F08
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 029E0022
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 029E0FD4
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 029E0090
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 029E0011
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 029E0000
.text C:\WINDOWS\System32\svchost.exe[1396] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 029E00BC
.text C:\WINDOWS\System32\svchost.exe[1396] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 028F0040
.text C:\WINDOWS\System32\svchost.exe[1396] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 028F0076
.text C:\WINDOWS\System32\svchost.exe[1396] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 028F001B
.text C:\WINDOWS\System32\svchost.exe[1396] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 028F0FE5
.text C:\WINDOWS\System32\svchost.exe[1396] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 028F0065
.text C:\WINDOWS\System32\svchost.exe[1396] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 028F0000
.text C:\WINDOWS\System32\svchost.exe[1396] ADVAPI32.dll!RegCreateKeyW 77DCBA55 2 Bytes JMP 028F0FC3
.text C:\WINDOWS\System32\svchost.exe[1396] ADVAPI32.dll!RegCreateKeyW + 3 77DCBA58 2 Bytes [B2, 8A] {MOV DL, 0x8a}
.text C:\WINDOWS\System32\svchost.exe[1396] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 028F0FD4
.text C:\WINDOWS\System32\svchost.exe[1396] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 028E0FCA
.text C:\WINDOWS\System32\svchost.exe[1396] msvcrt.dll!system 77BF93C7 5 Bytes JMP 028E0FE5
.text C:\WINDOWS\System32\svchost.exe[1396] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 028E0044
.text C:\WINDOWS\System32\svchost.exe[1396] msvcrt.dll!_open 77BFF566 5 Bytes JMP 028E000C
.text C:\WINDOWS\System32\svchost.exe[1396] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 028E0055
.text C:\WINDOWS\System32\svchost.exe[1396] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 028E001D
.text C:\WINDOWS\System32\svchost.exe[1396] WS2_32.dll!socket 71A14211 5 Bytes JMP 028D0000
.text C:\WINDOWS\System32\svchost.exe[1396] WININET.dll!InternetOpenA 408DD690 5 Bytes JMP 028C0000
.text C:\WINDOWS\System32\svchost.exe[1396] WININET.dll!InternetOpenW 408DDB09 5 Bytes JMP 028C0FE5
.text C:\WINDOWS\System32\svchost.exe[1396] WININET.dll!InternetOpenUrlA 408DF3A4 5 Bytes JMP 028C0FD4
.text C:\WINDOWS\System32\svchost.exe[1396] WININET.dll!InternetOpenUrlW 40926DDF 5 Bytes JMP 028C001B
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00770FEF
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 007700AB
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00770FC0
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0077008E
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0077007D
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0077005B
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 007700D0
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00770F7E
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00770F52
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 007700EB
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00770F41
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0077006C
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00770014
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00770FA5
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0077004A
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0077002F
.text C:\WINDOWS\System32\svchost.exe[1544] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00770F6D
.text C:\WINDOWS\System32\svchost.exe[1544] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00760FC0
.text C:\WINDOWS\System32\svchost.exe[1544] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 0076005B
.text C:\WINDOWS\System32\svchost.exe[1544] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 0076001B
.text C:\WINDOWS\System32\svchost.exe[1544] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 0076000A
.text C:\WINDOWS\System32\svchost.exe[1544] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00760F9E
.text C:\WINDOWS\System32\svchost.exe[1544] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00760FEF
.text C:\WINDOWS\System32\svchost.exe[1544] ADVAPI32.dll!RegCreateKeyW 77DCBA55 2 Bytes JMP 00760FAF
.text C:\WINDOWS\System32\svchost.exe[1544] ADVAPI32.dll!RegCreateKeyW + 3 77DCBA58 2 Bytes [99, 88]
.text C:\WINDOWS\System32\svchost.exe[1544] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 0076002C
.text C:\WINDOWS\System32\svchost.exe[1544] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00750089
.text C:\WINDOWS\System32\svchost.exe[1544] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00750064
.text C:\WINDOWS\System32\svchost.exe[1544] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00750038
.text C:\WINDOWS\System32\svchost.exe[1544] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00750000
.text C:\WINDOWS\System32\svchost.exe[1544] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00750049
.text C:\WINDOWS\System32\svchost.exe[1544] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 0075001D
.text C:\WINDOWS\System32\svchost.exe[1544] WS2_32.dll!socket 71A14211 5 Bytes JMP 00740FEF
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 009D0FEF
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 009D0F2D
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 009D0022
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 009D0F48
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 009D0F6F
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 009D0011
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 009D006B
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 009D004E
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 009D0EF7
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009D0090
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 009D0EE6
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 009D0F80
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 009D0FCA
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 009D003D
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 009D0FAF
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 009D0000
.text C:\WINDOWS\System32\svchost.exe[1592] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 009D0F08
.text C:\WINDOWS\System32\svchost.exe[1592] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 009C0FB9
.text C:\WINDOWS\System32\svchost.exe[1592] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 009C0F7C
.text C:\WINDOWS\System32\svchost.exe[1592] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 009C0FDE
.text C:\WINDOWS\System32\svchost.exe[1592] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 009C0FEF
.text C:\WINDOWS\System32\svchost.exe[1592] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 009C0F8D
.text C:\WINDOWS\System32\svchost.exe[1592] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 009C000A
.text C:\WINDOWS\System32\svchost.exe[1592] ADVAPI32.dll!RegCreateKeyW 77DCBA55 5 Bytes JMP 009C002F
.text C:\WINDOWS\System32\svchost.exe[1592] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 009C0FA8
.text C:\WINDOWS\System32\svchost.exe[1592] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 009B0069
.text C:\WINDOWS\System32\svchost.exe[1592] msvcrt.dll!system 77BF93C7 5 Bytes JMP 009B004E
.text C:\WINDOWS\System32\svchost.exe[1592] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 009B0033
.text C:\WINDOWS\System32\svchost.exe[1592] msvcrt.dll!_open 77BFF566 5 Bytes JMP 009B0FEF
.text C:\WINDOWS\System32\svchost.exe[1592] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 009B0FDE
.text C:\WINDOWS\System32\svchost.exe[1592] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 009B0018
.text C:\WINDOWS\System32\svchost.exe[1592] WS2_32.dll!socket 71A14211 5 Bytes JMP 009A0FEF
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C10000
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C10F66
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C10F77
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C1005B
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C10F9E
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C10036
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C10F3A
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C10076
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C10EFD
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C10F0E
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C100B1
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C10FAF
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C10FE5
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C10F55
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C10025
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C10FD4
.text C:\WINDOWS\System32\svchost.exe[1664] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C10F1F
.text C:\WINDOWS\System32\svchost.exe[1664] ADVAPI32.dll!RegOpenKeyExW 77DA6AAF 5 Bytes JMP 00C00000
.text C:\WINDOWS\System32\svchost.exe[1664] ADVAPI32.dll!RegCreateKeyExW 77DA776C 5 Bytes JMP 00C00F80
.text C:\WINDOWS\System32\svchost.exe[1664] ADVAPI32.dll!RegOpenKeyExA 77DA7852 5 Bytes JMP 00C00FAF
.text C:\WINDOWS\System32\svchost.exe[1664] ADVAPI32.dll!RegOpenKeyW 77DA7946 5 Bytes JMP 00C00FCA
.text C:\WINDOWS\System32\svchost.exe[1664] ADVAPI32.dll!RegCreateKeyExA 77DAE9F4 5 Bytes JMP 00C0003D
.text C:\WINDOWS\System32\svchost.exe[1664] ADVAPI32.dll!RegOpenKeyA 77DAEFC8 5 Bytes JMP 00C00FE5
.text C:\WINDOWS\System32\svchost.exe[1664] ADVAPI32.dll!RegCreateKeyW 77DCBA55 5 Bytes JMP 00C0002C
.text C:\WINDOWS\System32\svchost.exe[1664] ADVAPI32.dll!RegCreateKeyA 77DCBCF3 5 Bytes JMP 00C00011
.text C:\WINDOWS\System32\svchost.exe[1664] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00BF0025
.text C:\WINDOWS\System32\svchost.exe[1664] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00BF0F9A
.text C:\WINDOWS\System32\svchost.exe[1664] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00BF0000
.text C:\WINDOWS\System32\svchost.exe[1664] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\System32\svchost.exe[1664] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00BF0FAB
.text C:\WINDOWS\System32\svchost.exe[1664] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00BF0FC6
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) Code:
6.
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/07/02 17:53
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: 1394BUS.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\1394BUS.SYS
Address: 0xF754E000 Size: 57344 File Visible: - Signed: -
Status: -
Name: ACPI.sys
Image Path: ACPI.sys
Address: 0xF74DE000 Size: 188800 File Visible: - Signed: -
Status: -
Name: ACPI_HAL
Image Path: \Driver\ACPI_HAL
Address: 0x804D7000 Size: 2192256 File Visible: - Signed: -
Status: -
Name: afd.sys
Image Path: C:\WINDOWS\System32\drivers\afd.sys
Address: 0xA66BB000 Size: 138496 File Visible: - Signed: -
Status: -
Name: ALCXWDM.SYS
Image Path: C:\WINDOWS\system32\drivers\ALCXWDM.SYS
Address: 0xF68C6000 Size: 645824 File Visible: - Signed: -
Status: -
Name: amdk7.sys
Image Path: C:\WINDOWS\System32\DRIVERS\amdk7.sys
Address: 0xF6B08000 Size: 41856 File Visible: - Signed: -
Status: -
Name: atapi.sys
Image Path: atapi.sys
Address: 0xF7496000 Size: 96512 File Visible: - Signed: -
Status: -
Name: ati2cqag.dll
Image Path: C:\WINDOWS\System32\ati2cqag.dll
Address: 0xBF04A000 Size: 233472 File Visible: - Signed: -
Status: -
Name: ati2dvag.dll
Image Path: C:\WINDOWS\System32\ati2dvag.dll
Address: 0xBF012000 Size: 229376 File Visible: - Signed: -
Status: -
Name: ati2mtag.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ati2mtag.sys
Address: 0xF69F1000 Size: 880640 File Visible: - Signed: -
Status: -
Name: ati3duag.dll
Image Path: C:\WINDOWS\System32\ati3duag.dll
Address: 0xBF083000 Size: 2179072 File Visible: - Signed: -
Status: -
Name: ativvaxx.dll
Image Path: C:\WINDOWS\System32\ativvaxx.dll
Address: 0xBF297000 Size: 487424 File Visible: - Signed: -
Status: -
Name: ATMFD.DLL
Image Path: C:\WINDOWS\System32\ATMFD.DLL
Address: 0xBFFA0000 Size: 286720 File Visible: - Signed: -
Status: -
Name: audstub.sys
Image Path: C:\WINDOWS\System32\DRIVERS\audstub.sys
Address: 0xF7B02000 Size: 3072 File Visible: - Signed: -
Status: -
Name: bcm4sbxp.sys
Image Path: C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys
Address: 0xA5C79000 Size: 56192 File Visible: - Signed: -
Status: -
Name: Beep.SYS
Image Path: C:\WINDOWS\System32\Drivers\Beep.SYS
Address: 0xF7A72000 Size: 4224 File Visible: - Signed: -
Status: -
Name: BOOTVID.dll
Image Path: C:\WINDOWS\system32\BOOTVID.dll
Address: 0xF793E000 Size: 12288 File Visible: - Signed: -
Status: -
Name: Cdfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Address: 0xA6443000 Size: 63744 File Visible: - Signed: -
Status: -
Name: cdrom.sys
Image Path: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Address: 0xF6AD8000 Size: 62976 File Visible: - Signed: -
Status: -
Name: CLASSPNP.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\CLASSPNP.SYS
Address: 0xF758E000 Size: 53248 File Visible: - Signed: -
Status: -
Name: disk.sys
Image Path: disk.sys
Address: 0xF757E000 Size: 36352 File Visible: - Signed: -
Status: -
Name: drmk.sys
Image Path: C:\WINDOWS\system32\drivers\drmk.sys
Address: 0xF75FE000 Size: 61440 File Visible: - Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA64EB000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7A80000 Size: 8192 File Visible: No Signed: -
Status: -
Name: Dxapi.sys
Image Path: C:\WINDOWS\System32\drivers\Dxapi.sys
Address: 0xF6808000 Size: 12288 File Visible: - Signed: -
Status: -
Name: dxg.sys
Image Path: C:\WINDOWS\System32\drivers\dxg.sys
Address: 0xBF000000 Size: 73728 File Visible: - Signed: -
Status: -
Name: dxgthk.sys
Image Path: C:\WINDOWS\System32\drivers\dxgthk.sys
Address: 0xF7C59000 Size: 4096 File Visible: - Signed: -
Status: -
Name: Fastfat.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Address: 0xA6503000 Size: 143744 File Visible: - Signed: -
Status: -
Name: fdc.sys
Image Path: C:\WINDOWS\System32\DRIVERS\fdc.sys
Address: 0xF788E000 Size: 27392 File Visible: - Signed: -
Status: -
Name: Fips.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fips.SYS
Address: 0xF76DE000 Size: 44672 File Visible: - Signed: -
Status: -
Name: flpydisk.sys
Image Path: C:\WINDOWS\System32\DRIVERS\flpydisk.sys
Address: 0xF78BE000 Size: 20480 File Visible: - Signed: -
Status: -
Name: fltmgr.sys
Image Path: fltmgr.sys
Address: 0xF7476000 Size: 129792 File Visible: - Signed: -
Status: -
Name: Fs_Rec.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Address: 0xF7A70000 Size: 7936 File Visible: - Signed: -
Status: -
Name: ftdisk.sys
Image Path: ftdisk.sys
Address: 0xF74AE000 Size: 126336 File Visible: - Signed: -
Status: -
Name: gameenum.sys
Image Path: C:\WINDOWS\System32\DRIVERS\gameenum.sys
Address: 0xF7A06000 Size: 10624 File Visible: - Signed: -
Status: -
Name: giveio.sys
Image Path: giveio.sys
Address: 0xF7AF6000 Size: 1664 File Visible: No Signed: -
Status: -
Name: hal.dll
Image Path: C:\WINDOWS\system32\hal.dll
Address: 0x806EF000 Size: 131840 File Visible: - Signed: -
Status: -
Name: HTTP.sys
Image Path: C:\WINDOWS\System32\Drivers\HTTP.sys
Address: 0xA563E000 Size: 265728 File Visible: - Signed: -
Status: -
Name: i8042prt.sys
Image Path: C:\WINDOWS\System32\DRIVERS\i8042prt.sys
Address: 0xF6AE8000 Size: 52992 File Visible: - Signed: -
Status: -
Name: imapi.sys
Image Path: C:\WINDOWS\System32\DRIVERS\imapi.sys
Address: 0xF75EE000 Size: 42112 File Visible: - Signed: -
Status: -
Name: ipfltdrv.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys
Address: 0xF76BE000 Size: 32896 File Visible: - Signed: -
Status: -
Name: ipnat.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ipnat.sys
Address: 0xA6527000 Size: 152832 File Visible: - Signed: -
Status: -
Name: ipsec.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ipsec.sys
Address: 0xA67AD000 Size: 75264 File Visible: - Signed: -
Status: -
Name: isapnp.sys
Image Path: isapnp.sys
Address: 0xF752E000 Size: 37632 File Visible: - Signed: -
Status: -
Name: kbdclass.sys
Image Path: C:\WINDOWS\System32\DRIVERS\kbdclass.sys
Address: 0xF7896000 Size: 25216 File Visible: - Signed: -
Status: -
Name: KDCOM.DLL
Image Path: C:\WINDOWS\system32\KDCOM.DLL
Address: 0xF7A2E000 Size: 8192 File Visible: - Signed: -
Status: -
Name: kmixer.sys
Image Path: C:\WINDOWS\system32\drivers\kmixer.sys
Address: 0xA5433000 Size: 172416 File Visible: - Signed: -
Status: -
Name: ks.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ks.sys
Address: 0xF6964000 Size: 143360 File Visible: - Signed: -
Status: -
Name: KSecDD.sys
Image Path: KSecDD.sys
Address: 0xF744D000 Size: 92928 File Visible: - Signed: -
Status: -
Name: mfeavfk.sys
Image Path: C:\WINDOWS\system32\drivers\mfeavfk.sys
Address: 0xA56CF000 Size: 73088 File Visible: - Signed: -
Status: -
Name: mfebopk.sys
Image Path: C:\WINDOWS\system32\drivers\mfebopk.sys
Address: 0xF77E6000 Size: 28544 File Visible: - Signed: -
Status: -
Name: mfehidk.sys
Image Path: C:\WINDOWS\system32\drivers\mfehidk.sys
Address: 0xA654D000 Size: 207936 File Visible: - Signed: -
Status: -
Name: mfesmfk.sys
Image Path: C:\WINDOWS\system32\drivers\mfesmfk.sys
Address: 0xA5576000 Size: 33824 File Visible: - Signed: -
Status: -
Name: mnmdd.SYS
Image Path: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Address: 0xF7A74000 Size: 4224 File Visible: - Signed: -
Status: -
Name: mouclass.sys
Image Path: C:\WINDOWS\System32\DRIVERS\mouclass.sys
Address: 0xF789E000 Size: 23552 File Visible: - Signed: -
Status: -
Name: MountMgr.sys
Image Path: MountMgr.sys
Address: 0xF755E000 Size: 42368 File Visible: - Signed: -
Status: -
Name: Mpfp.sys
Image Path: C:\WINDOWS\System32\Drivers\Mpfp.sys
Address: 0xA672D000 Size: 159744 File Visible: - Signed: -
Status: -
Name: mrxsmb.sys
Image Path: C:\WINDOWS\System32\DRIVERS\mrxsmb.sys
Address: 0xA6580000 Size: 455680 File Visible: - Signed: -
Status: -
Name: Msfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Msfs.SYS
Address: 0xF78D6000 Size: 19072 File Visible: - Signed: -
Status: -
Name: msgpc.sys
Image Path: C:\WINDOWS\System32\DRIVERS\msgpc.sys
Address: 0xF763E000 Size: 35072 File Visible: - Signed: -
Status: -
Name: mssmbios.sys
Image Path: C:\WINDOWS\System32\DRIVERS\mssmbios.sys
Address: 0xF7A26000 Size: 15488 File Visible: - Signed: -
Status: -
Name: Mup.sys
Image Path: Mup.sys
Address: 0xF7283000 Size: 105344 File Visible: - Signed: -
Status: -
Name: NDIS.sys
Image Path: NDIS.sys
Address: 0xF7393000 Size: 182656 File Visible: - Signed: -
Status: -
Name: ndistapi.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ndistapi.sys
Address: 0xF7A16000 Size: 10112 File Visible: - Signed: -
Status: -
Name: ndisuio.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ndisuio.sys
Address: 0xA63B7000 Size: 14592 File Visible: - Signed: -
Status: -
Name: ndiswan.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ndiswan.sys
Address: 0xF688B000 Size: 91520 File Visible: - Signed: -
Status: -
Name: NDProxy.SYS
Image Path: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Address: 0xF765E000 Size: 40576 File Visible: - Signed: -
Status: -
Name: netbios.sys
Image Path: C:\WINDOWS\System32\DRIVERS\netbios.sys
Address: 0xF76CE000 Size: 34688 File Visible: - Signed: -
Status: -
Name: netbt.sys
Image Path: C:\WINDOWS\System32\DRIVERS\netbt.sys
Address: 0xA66DD000 Size: 162816 File Visible: - Signed: -
Status: -
Name: Npfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Npfs.SYS
Address: 0xF78DE000 Size: 30848 File Visible: - Signed: -
Status: -
Name: Ntfs.sys
Image Path: Ntfs.sys
Address: 0xF73C0000 Size: 574976 File Visible: - Signed: -
Status: -
Name: ntoskrnl.exe
Image Path: C:\WINDOWS\system32\ntoskrnl.exe
Address: 0x804D7000 Size: 2192256 File Visible: - Signed: -
Status: -
Name: Null.SYS
Image Path: C:\WINDOWS\System32\Drivers\Null.SYS
Address: 0xF7C29000 Size: 2944 File Visible: - Signed: -
Status: -
Name: ohci1394.sys
Image Path: ohci1394.sys
Address: 0xF753E000 Size: 61696 File Visible: - Signed: -
Status: -
Name: parport.sys
Image Path: C:\WINDOWS\System32\DRIVERS\parport.sys
Address: 0xF69A5000 Size: 80384 File Visible: - Signed: -
Status: -
Name: PartMgr.sys
Image Path: PartMgr.sys
Address: 0xF77B6000 Size: 19712 File Visible: - Signed: -
Status: -
Name: ParVdm.SYS
Image Path: C:\WINDOWS\System32\Drivers\ParVdm.SYS
Address: 0xF7AE0000 Size: 7040 File Visible: - Signed: -
Status: -
Name: pci.sys
Image Path: pci.sys
Address: 0xF74CD000 Size: 68224 File Visible: - Signed: -
Status: -
Name: PCIIDEX.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\PCIIDEX.SYS
Address: 0xF77AE000 Size: 28672 File Visible: - Signed: -
Status: -
Name: PnpManager
Image Path: \Driver\PnpManager
Address: 0x804D7000 Size: 2192256 File Visible: - Signed: -
Status: -
Name: portcls.sys
Image Path: C:\WINDOWS\system32\drivers\portcls.sys
Address: 0xF68A2000 Size: 147456 File Visible: - Signed: -
Status: -
Name: psched.sys
Image Path: C:\WINDOWS\System32\DRIVERS\psched.sys
Address: 0xF687A000 Size: 69120 File Visible: - Signed: -
Status: -
Name: ptilink.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ptilink.sys
Address: 0xF78AE000 Size: 17792 File Visible: - Signed: -
Status: -
Name: PxHelp20.sys
Image Path: PxHelp20.sys
Address: 0xF759E000 Size: 35712 File Visible: - Signed: -
Status: -
Name: rasacd.sys
Image Path: C:\WINDOWS\System32\DRIVERS\rasacd.sys
Address: 0xF723B000 Size: 8832 File Visible: - Signed: -
Status: -
Name: rasl2tp.sys
Image Path: C:\WINDOWS\System32\DRIVERS\rasl2tp.sys
Address: 0xF760E000 Size: 51328 File Visible: - Signed: -
Status: -
Name: raspppoe.sys
Image Path: C:\WINDOWS\System32\DRIVERS\raspppoe.sys
Address: 0xF761E000 Size: 41472 File Visible: - Signed: -
Status: -
Name: raspptp.sys
Image Path: C:\WINDOWS\System32\DRIVERS\raspptp.sys
Address: 0xF762E000 Size: 48384 File Visible: - Signed: -
Status: -
Name: raspti.sys
Image Path: C:\WINDOWS\System32\DRIVERS\raspti.sys
Address: 0xF78B6000 Size: 16512 File Visible: - Signed: -
Status: -
Name: RAW
Image Path: \FileSystem\RAW
Address: 0x804D7000 Size: 2192256 File Visible: - Signed: -
Status: -
Name: rdbss.sys
Image Path: C:\WINDOWS\System32\DRIVERS\rdbss.sys
Address: 0xA65F0000 Size: 175744 File Visible: - Signed: -
Status: -
Name: RDPCDD.sys
Image Path: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Address: 0xF7A76000 Size: 4224 File Visible: - Signed: -
Status: -
Name: redbook.sys
Image Path: C:\WINDOWS\System32\DRIVERS\redbook.sys
Address: 0xF6AC8000 Size: 57728 File Visible: - Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA5851000 Size: 49152 File Visible: No Signed: -
Status: -
Name: serenum.sys
Image Path: C:\WINDOWS\System32\DRIVERS\serenum.sys
Address: 0xF7A02000 Size: 15744 File Visible: - Signed: -
Status: -
Name: serial.sys
Image Path: C:\WINDOWS\System32\DRIVERS\serial.sys
Address: 0xF6AF8000 Size: 65536 File Visible: - Signed: -
Status: -
Name: speedfan.sys
Image Path: speedfan.sys
Address: 0xF7A34000 Size: 5248 File Visible: No Signed: -
Status: -
Name: sr.sys
Image Path: sr.sys
Address: 0xF7464000 Size: 73472 File Visible: - Signed: -
Status: -
Name: srv.sys
Image Path: C:\WINDOWS\System32\DRIVERS\srv.sys
Address: 0xA5FF7000 Size: 353792 File Visible: - Signed: -
Status: -
Name: swenum.sys
Image Path: C:\WINDOWS\System32\DRIVERS\swenum.sys
Address: 0xF7A6C000 Size: 4352 File Visible: - Signed: -
Status: -
Name: sysaudio.sys
Image Path: C:\WINDOWS\system32\drivers\sysaudio.sys
Address: 0xA61CB000 Size: 60800 File Visible: - Signed: -
Status: -
Name: tcpip.sys
Image Path: C:\WINDOWS\System32\DRIVERS\tcpip.sys
Address: 0xA6754000 Size: 361600 File Visible: - Signed: -
Status: -
Name: TDI.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\TDI.SYS
Address: 0xF78A6000 Size: 20480 File Visible: - Signed: -
Status: -
Name: termdd.sys
Image Path: C:\WINDOWS\System32\DRIVERS\termdd.sys
Address: 0xF764E000 Size: 40704 File Visible: - Signed: -
Status: -
Name: update.sys
Image Path: C:\WINDOWS\System32\DRIVERS\update.sys
Address: 0xF681C000 Size: 384768 File Visible: - Signed: -
Status: -
Name: USBD.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\USBD.SYS
Address: 0xF7A6E000 Size: 8192 File Visible: - Signed: -
Status: -
Name: usbehci.sys
Image Path: C:\WINDOWS\System32\DRIVERS\usbehci.sys
Address: 0xF7886000 Size: 30208 File Visible: - Signed: -
Status: -
Name: usbhub.sys
Image Path: C:\WINDOWS\System32\DRIVERS\usbhub.sys
Address: 0xF769E000 Size: 59520 File Visible: - Signed: -
Status: -
Name: USBPORT.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\USBPORT.SYS
Address: 0xF69B9000 Size: 147456 File Visible: - Signed: -
Status: -
Name: USBSTOR.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS
Address: 0xF78E6000 Size: 26368 File Visible: - Signed: -
Status: -
Name: usbuhci.sys
Image Path: C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Address: 0xF787E000 Size: 20608 File Visible: - Signed: -
Status: -
Name: vga.sys
Image Path: C:\WINDOWS\System32\drivers\vga.sys
Address: 0xF78CE000 Size: 20992 File Visible: - Signed: -
Status: -
Name: viaagp1.sys
Image Path: viaagp1.sys
Address: 0xF77BE000 Size: 32128 File Visible: - Signed: -
Status: -
Name: viaidexp.sys
Image Path: viaidexp.sys
Address: 0xF7A32000 Size: 6144 File Visible: - Signed: -
Status: -
Name: VIAPFD.SYS
Image Path: C:\WINDOWS\System32\Drivers\VIAPFD.SYS
Address: 0xF7C2A000 Size: 2880 File Visible: - Signed: -
Status: -
Name: VIDEOPRT.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS
Address: 0xF69DD000 Size: 81920 File Visible: - Signed: -
Status: -
Name: vmodem.sys
Image Path: vmodem.sys
Address: 0xF729D000 Size: 604224 File Visible: - Signed: -
Status: -
Name: VolSnap.sys
Image Path: VolSnap.sys
Address: 0xF756E000 Size: 53760 File Visible: - Signed: -
Status: -
Name: vpctcom.sys
Image Path: vpctcom.sys
Address: 0xF7331000 Size: 397472 File Visible: - Signed: -
Status: -
Name: vvoice.sys
Image Path: vvoice.sys
Address: 0xF75AE000 Size: 64576 File Visible: - Signed: -
Status: -
Name: wanarp.sys
Image Path: C:\WINDOWS\System32\DRIVERS\wanarp.sys
Address: 0xF76EE000 Size: 34560 File Visible: - Signed: -
Status: -
Name: watchdog.sys
Image Path: C:\WINDOWS\System32\watchdog.sys
Address: 0xF790E000 Size: 20480 File Visible: - Signed: -
Status: -
Name: wdmaud.sys
Image Path: C:\WINDOWS\system32\drivers\wdmaud.sys
Address: 0xA604E000 Size: 83072 File Visible: - Signed: -
Status: -
Name: Win32k
Image Path: \Driver\Win32k
Address: 0xBF800000 Size: 1851392 File Visible: - Signed: -
Status: -
Name: win32k.sys
Image Path: C:\WINDOWS\System32\win32k.sys
Address: 0xBF800000 Size: 1851392 File Visible: - Signed: -
Status: -
Name: WMILIB.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\WMILIB.SYS
Address: 0xF7A30000 Size: 8192 File Visible: - Signed: -
Status: -
Name: WMIxWDM
Image Path: \Driver\WMIxWDM
Address: 0x804D7000 Size: 2192256 File Visible: - Signed: -
Status: - |